Description
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH can obtain the admin credentials for the Cloud Foundry Platform through the logs of the NFS volume deploy errand.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7659 | Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH can obtain the admin credentials for the Cloud Foundry Platform through the logs of the NFS volume deploy errand. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2018-15797 |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T18:24:31.452Z
Reserved: 2018-08-23T00:00:00.000Z
Link: CVE-2018-15797
No data.
Status : Modified
Published: 2018-12-05T18:29:00.300
Modified: 2024-11-21T03:51:28.203
Link: CVE-2018-15797
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD